PT-2025-26840 · Onetrust · Onetrust Sdk

Published

2025-06-25

·

Updated

2025-06-26

·

CVE-2024-57708

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: OneTrust SDK version 6.33.0
Description: The issue allows a local attacker to cause a denial of service via the Object.setPrototypeOf, proto, and Object.assign components.
Recommendations: For OneTrust SDK version 6.33.0, consider disabling the use of Object.setPrototypeOf, proto, and Object.assign components as a temporary workaround until a patch is available.

Exploit

Fix

DoS

Resource Exhaustion

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2024-57708

Affected Products

Onetrust Sdk